GHSA-5g75-477j-2c2f
CRITICALCVE-2026-54617An unauthenticated path traversal in the LaunchServer HTTP file server (FileServerHandler) lets any remote actor read any file readable by the LaunchServer process (e.g. ../../../../etc/passwd). This is a generic arbitrary-file-read primitive, so the fix must address the traversal itself, not any specific file.
- Affected
- <= 5.7.11
- Fixed in
- not stated
- Weakness
- CWE-22
- Published
- 2026-07-02
- Source
- github